Skip to content

Unauthenticated Users Can View Sensitive Config Keys

Low
0xAda published GHSA-ph67-c355-52vm Oct 3, 2020

Package

RACTF Core (django)

Affected versions

<=41edf92

Patched versions

f3dc89b

Description

Impact

Unauthenticated users are able to get the value of sensitive config keys that would normally be hidden to everyone except admins.

Patches

All versions after commit f3dc89b(3/10/20) are patched.

References

f3dc89b

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2020-15235

Weaknesses

No CWEs

Credits